Server-Side Template Injection in DocsGPT by Arc53
CVE-2026-31020

9.8CRITICAL

Key Information:

Vendor

Arc53

Status
Vendor
CVE Published:
4 September 2026

What is CVE-2026-31020?

The DocsGPT application, in version 0.15.0 and earlier, features a custom prompt functionality that allows user-defined inputs during chatbot interactions. This feature uses Jinja templates to render user-supplied data without proper input validation or sandboxing, exposing the application to a server-side template injection vulnerability. An attacker, without any authentication, can exploit this by injecting harmful template expressions, potentially leading to full remote code execution on the server.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.